Menu

Monthly Archives: February 2019

Facebook tricked kids into in-game purchases, say privacy advocates
Adobe patches the same critical Reader flaw twice in one week

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A newer version of waagent is needed for several features of the Azure platform. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass.

LinuxSecurity.com: The package python-mysql-connector before version 8.0.15-1 is vulnerable to authentication bypass.

Nike’s $350 “Back to the Future” trainers crash, have feet of brick
Understanding VPN through open systems interconnection model
Major Android ad fraud scam campaign drains battery & eats data
Severe flaws in password managers let hackers extract clear-text passwords
Setting up a Django application on RHEL 8 Beta
Phishing Scam Cloaks Malware With Fake Google reCAPTCHA
Reddit Gold: Alice and Bob, Caught in a Web of Lies
Entrust Datacard lined up to unburden Thales of nCipher biz as price for Gemalto buyout
Video: HackerOne CEO on the Evolving Bug Bounty Landscape
Data Breaches of the Week: Tales of PoS Malware, Latrine Status
Threatpost News Wrap Podcast For Feb. 22

Reading Time: ~2 min. Email Phishers Find New Filter Bypass Since email filters have gained popularity over the last decade, scammers have been forced to adapt their attacks. To bypass a normal URL filter that would check for malicious links, these scammers have found a way to alter the “document relationship” file (xml.rels) and continue […]

Android banking malware distributed with fake Google reCAPTCHA
Taking Care of Your Personal Online Security (For Paranoids)
Infosec in spaaace! NCC and Surrey Uni to pore over satellite security
Facebook lets Android users block location tracking
Cyber-extortionists take aim at lucrative targets

A new report shines some light on multiple aspects of the growing threat of cyber-extortion The post Cyber-extortionists take aim at lucrative targets appeared first on WeLiveSecurity

Advertisers flee YouTube after video comments get even more disgusting
Microsoft fixes web server DDoS bug
Flash “security bypass” list hidden in Microsoft Edge browser
Threatpost Poll: Are Password Managers Too Risky?
Bluetooth “gas station” warning on Facebook – truth or hoax? [VIDEO]
WTF PDF: If at first you don’t succeed, you may be Adobe re-patching its Acrobat, Reader patches

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework and Visual Studio are prone to an security vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

ThreatList: Porn-Focused Malware Triples, Dark Web Loves It
Adobe Re-Patches Critical Acrobat Reader Flaw
Black-hat sextortionists required: Competitive salary and dental plan
Highly Critical Drupal RCE Flaw Affects Millions of Websites
Password managers leaking data in memory, but you should still use one
19-Year-Old WinRAR Flaw Plagues 500 Million Users
Hacker Lauri Love denied bid to get computers back
Toyota Australia driven offline by cyber attack, as heart hospital hit by ransomware
Sorry, we didn’t mean to keep that secret microphone a secret, says Google

Reading Time: ~3 min. “Internet of things” (IoT) is a term that’s becoming increasingly commonplace in our daily lives. Internet-connected devices are being designed and implemented at a rapid clip, especially in our own homes. The internet is not just at our fingertips anymore, but also at our beck and call with smart speakers and […]

How costly are sweetheart swindles?

And that’s on top of the heartache experienced by the tens of thousands of people who fall for romance scams each year The post How costly are sweetheart swindles? appeared first on WeLiveSecurity

Data breach rumours abound as UK Labour Party locks down access to member databases
Welcome to the sunlit uplands of HTTP/2, where a naughty request can send Microsoft’s IIS into a spin
139 US bars, restaurants and coffeeshops infected by credit-card stealing malware
Bored bloke takes control of British Army ‘psyops’ unit’s Twitter
Check yo self before you HyperWreck yo self: Cisco fixes gimme-root holes in HyperFlex, plus more security bugs
Where’s Zero Cool when you need him? Loose chips sink ships: How hackers could wreck container vessels
Smashing Security #116: Stalking debtors, Facebook farce, and a cyber insurance snag
No RESTful the wicked: If your website runs Drupal, you need to check for security updates – unless you enjoy being hacked
Behold… a WinRAR security bug that’s older than your child’s favorite YouTuber. And yes, you should patch this hole
Facebook hoax? Can you sniff out gas station card skimmers using Bluetooth?
Researcher: Not Hard for a Hacker to Capsize a Ship at Sea
Separ Malware Plucks Hundreds of Companies’ Credentials in Ongoing Phish

security update

Apple’s Shazam App Boots Facebook Ads and Other Third-Party SDKs
Password Manager Firms Blast Back at ‘Leaky Password’ Revelations
GitHub Increases Rewards, Scope For Bug-Bounty Program
Microsoft: Russia’s Fancy Bear Working to Influence EU Elections
Join me to learn more about Magecart attacks – and how to defend against them
Most & least radiation emitting smartphones in 2019
Torrent uploader CracksNow caught distributing GrandCrab ransomware
Dark Web hacker selling 92M new accounts on Dream market
Google in hot water after not revealing it had hidden a secret microphone in home alarm product
Who will stand up for European democracy? Us! says US software giant Microsoft
Virus attack! Hackers unleash social media worm after bug report ignored
Facebook tracks users it thinks may harm its employees
Google’s working on stopping sites from blocking Incognito mode
Siegeware: When criminals take over your smart building

Siegeware is what you get when cybercriminals mix the concept of ransomware with building automation systems: abuse of equipment control software to threaten access to physical facilities The post Siegeware: When criminals take over your smart building appeared first on WeLiveSecurity

The man suing Apple over two-factor authentication has ‘previous’
Password managers may leave your online crown jewels ‘exposed in RAM’ to malware – but hey, they’re still better than the alternative
Unearthed emails could be smoking gun in epic GDPR battle against Google, adtech giants
Download Kali Linux 2019.1 with Metasploit 5.0
Microsoft to Kill Updates for Legacy OS Using SHA-1
ThreatList: APT Adversaries Up the Ante on Speed, Target Telecom

security update

security update

security update

New GandCrab Decryptor Unlocks Files of Updated Ransomware
ATM Jackpotting Malware Hones Its Heist Tools
Facebook flaw could have allowed an attacker to hijack accounts
Rietspoof malware distributes ransomware via messaging apps
Accused hacker Lauri Love loses legal bid to reclaim seized IT gear
Switzerland offers cash for finding security holes in its e-voting system

Anybody with hacking prowess can take a crack at reading votes or even rigging the vote count itself The post Switzerland offers cash for finding security holes in its e-voting system appeared first on WeLiveSecurity

Millions of “private” medical helpline calls exposed on internet
Thousands of Android apps bypass Advertising ID to track users
Revealed: Numbers show extent of security fears about security biz Kaspersky Lab
If you think your deleted Twitter DMs are sliding into the trash, you’re wrong
Facebook acts like a law-breaking ‘digital gangster’, says official report
Fake text generator is so good its creators don’t want to release full version
Consistent security by crypto policies in Red Hat Enterprise Linux 8
It starts with Linux: How Red Hat is helping to counter Linux container security flaws
Understanding the Red Hat Enterprise Linux random number generator interface
Hardening ELF binaries using Relocation Read-Only (RELRO)
What data privacy means and how to guard it in 2019
Preparing for Identity Management in Red Hat Enterprise Linux 8
Red Hat Global Customer Tech Outlook 2019: Automation, cloud, & security lead funding priorities